PT-2006-4617 · Zen Cart · Zen Cart

O Y

·

Published

2006-07-21

·

Updated

2018-10-17

·

CVE-2006-3757

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zen Cart version 1.3.0.2
Description The issue allows remote attackers to obtain sensitive information via empty array parameters, which reveals the installation path in an error message. This is achieved by manipulating the GET[], SESSION[], POST[], or COOKIE[] arrays.
Recommendations For Zen Cart version 1.3.0.2, consider restricting access to the index.php file until a patch is available, or apply configuration changes to prevent the exposure of sensitive information through error messages.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-3757

Affected Products

Zen Cart